craftcms/cms is vulnerable to Authorization Bypass
78
High Risk
Craft CMS 5.10.11 fixes ten independently reported security issues. GHSA-5mjc-jqcw-6vrp exposed aggregate metadata for restricted asset volumes; GHSA-ccpq-mw3m-wwg2 allowed inline entry saves into unauthorized sections; GHSA-5fjj-496j-2qqf allowed administrator-stored site-name XSS; GHSA-9xvf-7w97-83mv allowed unauthorized replacement or deletion of conflicting assets; GHSA-242m-9wq7-vhwq could preserve administrator status when a deactivated account was reused during public registration; GHSA-3wcr-p33w-528f bypassed GraphQL site scope in entry mutations; GHSA-2f55-h4xr-92p2 allowed unauthorized provisional-draft deletion; GHSA-5fh8-74j8-mvcp propagated draft authorization to canonical per-site deletion; GHSA-329j-cx85-8r56 allowed replacement of peer-owned asset files; and GHSA-6qw4-cjqw-fj72 allowed a non-admin user administrator to mint an administrator password-reset URL. A deployment within the vulnerable range may be exposed to one or more of these issues depending on its enabled features and permission model.
You are affected if you are using a version that falls within the vulnerable range and your deployment permits control panel users, public registration with email verification disabled, or scoped GraphQL entry mutations.
craftcms/cms is vulnerable to Authorization Bypass in versions 5.0.0 - 5.10.10.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.